VB Blog

VB2019 paper: Why companies need to focus on a problem they do not know they have

Posted by   Virus Bulletin on   Mar 20, 2020

Often unbeknownst to network administrators, many company networks are used to download child sexual abuse material. In a paper presented at VB2019 in London, NetClean’s Richard Matti and Anna Creutz looked at this problem and what companies can do, ultimately, to help safeguard children. Today we publish their full paper.

Read more  

VB2020 update - currently business as usual

Posted by   Virus Bulletin on   Mar 16, 2020

Here at VB we are keeping a close eye on the global situation regarding the COVID-19 outbreak and the various travel restrictions and health advice, but in the meantime planning and arrangements for VB2020 are going ahead as usual, including the selection of papers.

Read more  

VB2019 paper: Defeating APT10 compiler-level obfuscations

Posted by   Virus Bulletin on   Mar 13, 2020

At VB2019 in London, Carbon Black researcher Takahiro Haruyama presented a paper on defeating compiler-level obfuscations used by the APT10 group. Today we publish both Takahiro's paper and the recording of his presentation.

Read more  

VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers

Posted by   Virus Bulletin on   Mar 12, 2020

At VB2019 in London Michael Raggi (Proofpoint) and Ghareeb Saad (Anomali) presented a paper on the 'Royal Road' exploit builder (or weaponizer) and how the properties of RTF files can be used to track weaponizers and their users. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 presentation: Nexus between OT and IT threat intelligence

Posted by   Virus Bulletin on   Mar 11, 2020

Operational technology, the mission critical IT in ICS, shares many similarities with traditional IT systems, but also some crucial differences. During the Threat Intelligence Practitioners’ Summit at VB2019, Dragos cyber threat intelligence analyst Selena Larson gave a keynote on these similarities and differences. Today we release the recording of her presentation.

Read more  

VB2019 paper: Kimsuky group: tracking the king of the spear-phishing

Posted by   Virus Bulletin on   Mar 10, 2020

In a paper presented at VB2019 in London, researchers fron the Financial Security Institute detailed the tools and activities used by the APT group 'Kimsuky', some of which they were able to analyse through OpSec failures by the group. Today, we publish their paper.

Read more  

VB2019 paper: Play fuzzing machine - hunting iOS and macOS kernel vulnerabilities automatically and smartly

Posted by   Virus Bulletin on   Mar 9, 2020

In a paper presented at VB2019 in London, Trend Micro researchers Lilang Wu and Moony Li explained how the hunt for vulnerabilities in MacOS and iOS operating systems can be made both smarter and more automatic. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Finding drive-by rookies using an automated active observation platform

Posted by   Virus Bulletin on   Mar 6, 2020

In a last-minute paper presented at VB2019 in London, Rintaro Koike (NTT Security) and Yosuke Chubachi (Active Defense Institute, Ltd) discussed the platform they have built to automatically detect and analyse exploit kits. Today we publish the recording of their presentation.

Read more  

VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation state adversary

Posted by   Virus Bulletin on   Feb 28, 2020

The activities of China-based threat actor PKPLUG were detailed in a VB2019 paper by Palo Alto Networks researcher Alex Hinchliffe, who described the playbook of this long-standing adversary. Today we publish both Alex's paper and the recording of his presentation.

Read more  

VB2019 paper: Static analysis methods for detection of Microsoft Office exploits

Posted by   Virus Bulletin on   Feb 25, 2020

Today we publish the VB2019 paper and presentation by McAfee researcher Chintan Shah in which he described static analysis methods for the detection of Microsoft Office exploits.

Read more  

Search blog

Call for papers: AVAR 2004

AVAR calls for papers
AVAR calls for papers AVAR (the Association of anti-Virus Asia Researchers) has issued a call for papers for AVAR 2004 in Tokyo, which will take place 25-26 November 2004 in… https://www.virusbulletin.com/blog/2004/05/call-papers-avar-2004/

May

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/05/

Symantec vulnerabilities

eEye reports four new Symantec vulnerabilities
eEye reports four new Symantec vulnerabilities eEye Digital Security has reported that it has discovered four new vulnerabilities affecting Symantec products. Products affected… https://www.virusbulletin.com/blog/2004/04/symantec-vulnerabilities/

Business news

Acquisitions and new product lines
Acquisitions and new product lines UK-based web and email filtering company SurfControl revealed plans last month to acquire California-based email security firm MessageSoft Inc.… https://www.virusbulletin.com/blog/2004/04/business-news/

No bull?

Eset vs. BullGuard
Eset vs. BullGuard Recently it was brought to VB’s attention that affiliates of BullGuard have been cruising in the slipstream of Eset’s NOD32 product range. Visitors to the… https://www.virusbulletin.com/blog/2004/04/no-bull/

April

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/04/

New sentencing, new legislation

United States Sentencing Commission gets busy...
United States Sentencing Commission gets busy... The United States Sentencing Commission (USSC) — the body tasked with refining the sentencing portions of new legislation — met… https://www.virusbulletin.com/blog/2004/04/new-sentencing-new-legislation/

Shrinking violets

Consolidation in the anti-spam industry
Consolidation in the anti-spam industry A report released by Gartner last month predicts consolidation in the anti-spam industry and a rapid contraction of the pool of anti-spam… https://www.virusbulletin.com/blog/2004/04/shrinking-violets/

Patent for Postini

Postini wins U.S. patent for email filtering
Postini wins U.S. patent for email filtering Managed email security company Postini has been granted a U.S. patent for email filtering technology.According to the patent, any… https://www.virusbulletin.com/blog/2004/03/patent-postini/

Roll up, roll up

AOL raffles spammer's Porsche
AOL raffles spammer's Porsche Taking a new angle on hitting spammers where it hurts, AOL is offering its members the opportunity to win a luxury car seized as part of a court… https://www.virusbulletin.com/blog/2004/03/roll-roll/

New kid on the certification block

CheckVir starts certification program
CheckVir starts certification program At the start of this year, CheckVir became the latest independent organisation to offer certification for anti-virus products, when the… https://www.virusbulletin.com/blog/2004/03/new-kid-certification-block/

A bit of R&R

Man. Loves. His. Spam. No really.
Man. Loves. His. Spam. No really. Some choose Yoga, others choose a glass of wine and a soak in a hot bath, and some, apparently, choose reading spam as their preferred method of… https://www.virusbulletin.com/blog/2004/03/bit-r-amp-r/

News summary

AMD introduces hardware-level AV protection
AMD introduces hardware-level AV protection AMD has launched its new Athlon 64 FX processor at the CeBIT trade show in Hanover, Germany. Aimed primarily at the PC gamer market,… https://www.virusbulletin.com/blog/2004/03/news-summary/

ISPs refile lawsuits

AOL and EarthLink refile suits against spammers
AOL and EarthLink refile suits against spammers US Internet service providers AOL and EarthLink have each refiled lawsuits against prolific spammers. A Florida man and married… https://www.virusbulletin.com/blog/2004/03/isps-refile-lawsuits/

March

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/03/

Fine for dialler spam

UK watchdog fines US company for sending spam
UK watchdog fines US company for sending spam A UK watchdog has fined a US company for sending spam. The fine was imposed by the UK's regulatory body for the premium rate… https://www.virusbulletin.com/blog/2004/03/fine-dialler-spam/

SMS spam goes down Down Under

Anti-spam code of conduct proves successful
Anti-spam code of conduct proves successful Australia's Telecommunications Industry Ombudsman reports that a code of conduct aimed at preventing SMS spam has been highly… https://www.virusbulletin.com/blog/2004/03/sms-spam-goes-down-down-under/

Errata: Windows NT comparative review

After re-testing, Alwil's AVAST! product gains a VB 100% award.
After re-testing, Alwil's AVAST! product gains a VB 100% award. The results were reviewed for two products in the Windows NT comparative review (VB February 2004, p.12), with the… https://www.virusbulletin.com/blog/2004/02/errata-windows-nt-comparative-review/

China sets deadline for spammers

China blacklists offending IP addresses
China blacklists offending IP addresses The Internet Society of China's Anti-Spam Coordination Team (ASCT) has published a blacklist of mail servers sending spam. The list… https://www.virusbulletin.com/blog/2004/02/china-sets-deadline-spammers/

Plans, acquisitions and royalty

NAI makes plans, Symantec acquires software manufacturer, Sophos receives royal visitors
NAI makes plans, Symantec acquires software manufacturer, Sophos receives royal visitors Network Associates Inc. (NAI) has unveiled plans to provide its customers with information… https://www.virusbulletin.com/blog/2004/02/plans-acquisitions-and-royalty/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.